Feed
Bounty Rolling

Puffer bug bounty on Sherlock: up to 100,000 USDC

Puffer pays up to 100,000 USDC for bugs in its Ethereum contracts. The Sherlock program has been live since 17 August 2026.

The Puffer bug bounty runs on Sherlock. It pays for bugs in Puffer's core contracts on Ethereum and in the bridged token contracts Puffer controls on other chains. The program has been live since 17 August 2026 and has no end date.

Rewards are paid in USDC. A critical bug pays 25,000 to 100,000 USDC, a high severity bug pays 10,000 to 25,000 USDC, and a medium bug pays 1,000 to 3,000 USDC. For a critical bug the reward is 10 percent of the funds directly affected, with a floor of 25,000 USDC and a ceiling of 100,000 USDC. The amount of funds at risk is measured when the report is sent.

Every report needs a coded proof of concept and steps to run it. Reports go only through Sherlock. A researcher must not publish the bug until Puffer has checked it, shipped a fix, and allowed disclosure. Testing stays on a local setup or a test network, not on the public mainnet.

Findings that need a trusted role to act against the protocol are out of scope. So are incorrect data from outside oracles, issues already named in published audits, and bugs in third party bridges or in EigenLayer and Lido contracts that Puffer does not control. A new path that an earlier fix does not cover can still be eligible.

Source · audits.sherlock.xyz/bug-bounties/355 Published 17 August 2026 · Added here 27 September 2026